Listen to the article
Coldcard’s firmware was not doing that. According to a report published by Block’s Bitcoin engineering and security teams, a build setting told the device to skip its own hardware randomness generator, and a check in a supporting library tested only whether that setting existed rather than whether it was switched on.
Key generation quietly fell through to a basic software substitute seeded from the chip’s serial number and clock registers.
None of those are secrets. The serial number is fixed factory metadata, and the clock values are timing state an attacker can narrow down or measure on a device of their own. Block traced the change to a commit dated March 1, 2021, shipped in firmware 4.0.0 that month.
As such, Coinkite warned users who generated a seed on an Mk3 running version 4.0.1 or later, and said “Mk4, Q and Mk5 are not affected based on our early analysis.”
Block said it disclosed its findings to Coinkite, whose team acknowledged them. Both companies describe their analyses as preliminary, and Block said it published without full testing to confirm exploitability because exploitation was already under way.
The exposure runs past wallet seeds. The same generator produced Coldcard’s paper wallet private keys, where the output becomes the key directly with no further derivation, along with seed-splitting masks, device cloning keys and Key Teleport transfers.
Read the full article here
Fact Checker
Verify the accuracy of this article using AI-powered analysis and real-time sources.

